# Query string with default\_operator as AND works differently in v2.4 and v6.8

**URL:** <https://discuss.elastic.co/t/query-string-with-default-operator-as-and-works-differently-in-v2-4-and-v6-8/290476>\
**Category:** Elasticsearch\
**Tags:** eql-elastic-query-language\
**Created:** [November 29, 2021, 5:57pm UTC](https://discuss.elastic.co/t/query-string-with-default-operator-as-and-works-differently-in-v2-4-and-v6-8/290476 "2021-11-29T17:57:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Syed\_Souban](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syed_souban/32/96882_2.png) [@Syed\_Souban](https://discuss.elastic.co/u/Syed_Souban)\
**Post date:** [November 29, 2021, 5:57pm UTC](https://discuss.elastic.co/t/query-string-with-default-operator-as-and-works-differently-in-v2-4-and-v6-8/290476/1 "2021-11-29T17:57:31Z")

</div>

The `query_string` query seems to be returning the documents that match all the terms across fields specified in the `fields` parameter in ES 2.4 whereas in ES 6.8 documents that match all the terms per field are returned.

Steps to reproduce:  
Insert the following documents into both ES 2.4 and ES 6.8 clusters:

```auto
PUT yields_test/il4/1
{
    "security_name":"high term1",
    "doc_type":"YIELDS"
}

PUT yields_test/il4/2
{
    "security_name":"high term2",
    "doc_type":"YIELDS"
}

PUT yields_test/il4/3
{
    "security_name":"low term2",
    "doc_type":"YIELDS"
}

PUT yields_test/il4/4
{
    "security_name":"low term1",
    "doc_type":"YIELDS"
}

PUT yields_test/il4/5
{
    "security_name":"high yield",
    "doc_type":"YIELDS"
}

PUT yields_test/il4/6
{
    "security_name":"high yields",
    "doc_type":"YIELDS"
}

PUT yields_test/il4/7
{
    "security_name":"high term3",
    "doc_type":"YIELD"
}

```

And try to search with the following `query_string` query in both of them:

```auto
GET yields_test/_search
{
    "query": {
        "query_string": {
           "fields": [
              "security_name",
                  "doc_type"
           ], 
           "query": "high yield",
           "default_operator": "AND"
        }
    }
}

```

ES 2.4 returns the following documents:

```auto
[
         {
            "_index": "yields_test",
            "_type": "il4",
            "_id": "7",
            "_score": 0.5098911,
            "_source": {
               "security_name": "high term3",
               "doc_type": "YIELD"
            }
         },
         {
            "_index": "yields_test",
            "_type": "il4",
            "_id": "5",
            "_score": 0.08322528,
            "_source": {
               "security_name": "high yield",
               "doc_type": "YIELDS"
            }
         }
      ]

```

whereas ES 6.8 returns the following:

```auto
[
         {
            "_index": "yields_test",
            "_type": "il4",
            "_id": "5",
            "_score": 0.5753642,
            "_source": {
               "security_name": "high yield",
               "doc_type": "YIELDS"
            }
         }
]

```

As we can see, ES 2.4 is matching the query `high yield` across the fields `security_name` and `doc_type` but ES 6.8 is not.

Why is there a difference between the two? I expect ES 6.8 to return the documents like ES 2.4. Did something change between the versions? Am I missing something? How do I return the same documents in ES 6.8?

---

<div class="post-metadata">

**Author:** ![Syed\_Souban](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syed_souban/32/96882_2.png) [@Syed\_Souban](https://discuss.elastic.co/u/Syed_Souban)\
**Post date:** [November 29, 2021, 6:19pm UTC](https://discuss.elastic.co/t/query-string-with-default-operator-as-and-works-differently-in-v2-4-and-v6-8/290476/2 "2021-11-29T18:19:57Z")

</div>

I was able to find what changed between the versions by using the `profile` field in the request body.  
The Lucene query which is created is different for both.

Lucene query generated by ES 2.4:  
`+(security_name:high | doc_type:high) +(security_name:yield | doc_type:yield)`

By ES 6.8:  
`((+security_name:high +security_name:yield) | (+doc_type:high +doc_type:yield))`

My other question about how to return the same documents in ES 6.8 still remains.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 29, 2021, 8:49pm UTC](https://discuss.elastic.co/t/query-string-with-default-operator-as-and-works-differently-in-v2-4-and-v6-8/290476/3 "2021-11-29T20:49:00Z")

</div>

Welcome to our community! 😃

Unfortunately both 2.X and 6.8 are [EOL](https://www.elastic.co/support/eol) and no longer supported. I would recommend upgrading to a supported version, 7.15 is latest.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 27, 2021, 8:49pm UTC](https://discuss.elastic.co/t/query-string-with-default-operator-as-and-works-differently-in-v2-4-and-v6-8/290476/4 "2021-12-27T20:49:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
